Vendor
SpiderFoot versions 4.0 and earlier are vulnerable to stored cross-site scripting (XSS) due to improper HTML sanitization in correlation titles, allowing attackers to execute arbitrary JavaScript in an operator's browser.